Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 51/1777
6.5
CVE-2026-14548

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of

5.2
CVE-2026-12052

The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.

4.6
CVE-2026-12051

The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer der

5.9
CVE-2026-11894

The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the

6.4
CVE-2026-16974

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site

5.9
CVE-2026-11893

The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetoo

6.5
CVE-2026-24330

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a mali

4.9
CVE-2026-24329

A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload i

6.3
CVE-2026-66779

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker co

5.3
CVE-2026-66778

SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A

5.9
CVE-2026-66777

SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D

5.9
CVE-2026-66776

SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under spec

4.3
CVE-2026-66775

SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent

5.9
CVE-2026-66773

A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data i

4.3
CVE-2026-66772

SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer

6.1
CVE-2026-66771

SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted applicatio

6.3
CVE-2026-66770

Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL

4.3
CVE-2026-66764

Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user

4.3
CVE-2026-66761

SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s

6.4
CVE-2026-66760

SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges

6.5
CVE-2026-58248

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci

5.3
CVE-2026-58247

SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul

4.3
CVE-2026-58244

SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati

4.2
CVE-2026-58241

SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privi

5.9
CVE-2026-58238

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could

5.9
CVE-2026-58237

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with l

5.5
CVE-2026-58236

SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing securit

6.3
CVE-2026-58235

SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer

5.3
CVE-2026-40130

SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated atta

4.3
CVE-2026-72919

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7

5.4
CVE-2026-72918

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7

5.9
CVE-2026-72917

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti

4.4
CVE-2026-6426

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size

4.3
CVE-2026-73035

npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t

6.5
CVE-2026-73033

Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmi

4.3
CVE-2026-72912

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec

6.5
CVE-2026-72908

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template

6.5
CVE-2026-72907

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function

4.3
CVE-2026-72906

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email

5.4
CVE-2026-72743

SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb

5.5
CVE-2026-18942

A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th

6.5
CVE-2026-16456

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex

6.5
CVE-2026-72873

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/

6.1
CVE-2026-69116

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives.

6.5
CVE-2026-69114

Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b

4.8
CVE-2026-44401

Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that

6.7
CVE-2026-71969

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt a

6.7
CVE-2026-71968

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application lo

5.5
CVE-2026-71967

OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pse

6.5
CVE-2026-71964

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started